Information disclosure in Zoom Video Communications, Inc. products - CVE-2022-28764
Published: November 11, 2022
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to the application does not clear data from the local SQL database after a meeting ends and also uses an insufficiently secure per-device key to encrypt meetings data. A local user can obtain meeting information such as in-meeting chat for the previous meeting attended from that local user account.
Affected software
Zoom Workplace App for Android
Zoom Workplace Desktop App for Windows
Zoom Workplace Desktop App for macOS
Zoom Workplace Desktop App for Linux
Zoom Rooms Client for Windows
Zoom Rooms Client for macOS
Virtual Desktop Infrastructure (VDI)
How to mitigate CVE-2022-28764
Zoom Workplace Desktop App for Windows - update to 5.12.6 10137
Zoom Workplace Desktop App for macOS - update to 5.12.6 12435
Zoom Workplace App for Android - update to 5.12.8 9880
Zoom Workplace Desktop App for Linux - update to 5.12.6 173
Zoom Rooms Client for Windows - update to 5.12.6 2076
Zoom Rooms Client for macOS - update to 5.12.6 1918
Virtual Desktop Infrastructure (VDI) - update to 5.12.6